CVE-2026-21258

medium Microsoft
CVSS v3 Base Score
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Published: February 10, 2026
Last Modified: March 13, 2026
Vendor: Microsoft
Source: MITRE

Description

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CWE

CWE-20

Affected Products

Microsoft Microsoft 365 Apps for EnterpriseMicrosoft Microsoft Excel 2016Microsoft Microsoft Office 2019Microsoft Microsoft Office LTSC 2021Microsoft Microsoft Office LTSC 2024Microsoft Microsoft Office LTSC for Mac 2021Microsoft Microsoft Office LTSC for Mac 2024Microsoft Office Online Server

References